1. Regulatory Compliance Framework
Binary Labs operates in strict compliance with the applicable Indian data protection laws, including:
- The Digital Personal Data Protection (DPDP) Act, 2023: Governing the lawful, consent-driven collection, storage, and processing of digital personal data across India.
- The Information Technology Act, 2000 (and 2008 Amendment): Specifically the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).
- CERT-In Directions: Adherence to the Indian Computer Emergency Response Team directives regarding mandatory incident reporting and cybersecurity baseline requirements.
2. Data Roles & Absolute Ownership
In relation to data uploaded to our SaaS applications (such as solar customer contact information, rooftop site surveys, electricity bills, and quotations):
- You are the Data Fiduciary (Data Controller): You maintain 100% legal ownership, custody, and control over your customer relationships, pricing rules, vendor POs, and team logs.
- Binary Labs is the Data Processor: We process and store your data strictly on your behalf to deliver the requested software services. We will never sell, lease, rent, or monetize your customer data, lead phone numbers, or commercial margins to any third party or competitor.
- No AI Model Training on Private Data: Your internal proposals, quotations, customer KYC, and survey photos are strictly private and never used to train global public AI models without your explicit written authorization.
3. Technical & Infrastructure Security
We employ robust, multi-layered defense-in-depth architecture to secure our cloud environment:
- Data Storage Localization (India): All database instances, document storage buckets, and server compute run within Indian sovereign cloud regions (AWS Asia Pacific - Mumbai `ap-south-1` and Hyderabad `ap-south-2`), ensuring your data never leaves Indian borders.
- Encryption at Rest: All database clusters, disk volumes, and document vaults are encrypted at rest using industry-standard AES-256 (Advanced Encryption Standard).
- Encryption in Transit: All data transmitted between your browser or mobile application and our backend endpoints is encrypted using modern TLS 1.3 / HTTPS cryptographic protocols with HSTS enforcement.
- Multi-Tenant Isolation: Strict row-level security and tenant isolation ensure that no user or organization can ever view, query, or leak another tenant's project records.
- Daily Automated Backups: Point-in-time database snapshots are performed daily and replicated across multiple availability zones within India with automated disaster recovery protocols.
4. Role-Based Access Control (RBAC) & Authentication
Our platform enforces granular permission controls:
- Principle of Least Privilege: Team members are only granted permissions required for their specific role (e.g. Sales Rep, Site Surveyor, Project Manager, Accountant, Administrator).
- Session Protection: Secure, HTTP-only authentication tokens with automatic timeout and protection against CSRF and XSS attacks.
- Activity Audit Logging: Sensitive events such as proposal exports, price edits, and permission changes are timestamped in system audit logs.
5. Rights of Data Principals (Under DPDP Act 2023)
In accordance with the DPDP Act 2023, data principals whose personal data is processed through our platforms enjoy the following enforceable rights:
- Right to Access Information: The right to obtain a summary of personal data being processed and the identities of any authorized processing entities.
- Right to Correction & Erasure: The right to update inaccurate personal data or request permanent deletion of records when no longer necessary for legal or operational purposes.
- Right of Grievance Redressal: Accessible mechanisms to register privacy concerns with our designated Data Protection Officer.
- Right to Nominate: The right to nominate an individual to exercise data privacy rights in the event of death or incapacity.
6. Data Retention & Permanent Deletion
We retain customer records only for as long as your account remains active or as required by Indian taxation and legal statutes (e.g. GST invoice retention mandates). Upon subscription termination or upon receiving a formal deletion request:
- All customer database rows, site photos, and document vaults are purged from primary servers within 30 days.
- Encrypted backup archives overwrite purged data naturally across standard backup rotation cycles within 90 days.
7. Incident Response & Breach Notification
We maintain a structured Incident Response Plan. In the unlikely event of a verified security incident affecting personal data:
- Our security operations team initiates immediate containment and remediation procedures.
- Affected clients and regulatory authorities (including CERT-In and the Data Protection Board of India) will be notified in full accordance with statutory notification timelines.
8. Contact Our Data Protection Officer (DPO)
If you have questions regarding our data protection policies, wish to exercise your rights under the DPDP Act 2023, or need to report a security inquiry, please contact our compliance desk:
Binary Labs Privacy & Compliance Desk
Attn: Data Protection Officer (DPO)
Nashik, Maharashtra, India